Description
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Metadata Plugin component of Oracle Enterprise Manager Base Platform, enabling a low‑privileged attacker with network access via HTTPS to compromise the platform and gain full control. This flaw is identified as CWE-269. The CVSS 3.1 base score of 8.8 signals high confidentiality, integrity, and availability impact, and the vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates that remote exploitation does not require user interaction.

Affected Systems

Oracle Enterprise Manager Base Platform version 13.5 and version 24.1 are affected. The vulnerability is present in the Metadata Plugin component of these deployments.

Risk and Exploitability

The CVSS score of 8.8 flags the vulnerability as high severity, while the EPSS score of <1% implies a low to very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly available exploit is known as of this analysis. Based on the description, the likely attack vector involves a low‑privileged attacker who can reach the HTTPS interface of an unpatched Enterprise Manager instance; successful exploitation would lead to takeover of the platform and unrestricted access to all managed assets.

Generated by OpenCVE AI on August 4, 2026 at 17:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a non‑affected version as described in the Oracle CPU July 2026 advisory;
  • Restrict network access to the Enterprise Manager HTTPS port to trusted hosts or a VPN‑only connection;
  • Enforce strict role‑based access controls and regularly review privilege assignments;
  • Monitor system logs and implement intrusion detection for anomalous activity on the Metadata Plugin endpoint.

Generated by OpenCVE AI on August 4, 2026 at 17:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Oracle EM Base Platform Metadata Plugin Remote Takeover Vulnerability

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Oracle EM Base Platform Metadata Plugin Remote Takeover Vulnerability

Wed, 29 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle Enterprise Manager Base Platform Metadata Plugin
Weaknesses CWE-284

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle Enterprise Manager Base Platform Metadata Plugin
Weaknesses CWE-284

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Manager Base Platform
CPEs cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Manager Base Platform
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Manager Base Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T13:48:10.433Z

Reserved: 2026-05-18T15:55:10.315Z

Link: CVE-2026-46995

cve-icon Vulnrichment

Updated: 2026-07-23T13:48:04.604Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:04.780

Modified: 2026-07-24T19:04:40.420

Link: CVE-2026-46995

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:00:14Z

Weaknesses
  • CWE-269

    Improper Privilege Management